Privacy Policy

PolyCal ("we", "us") is a private-group scheduling application. This policy describes how we handle information in the running service, based on the product's database schema, authentication, and configured integrations.

Effective date: July 23, 2026

1. Who this applies to

PolyCal is used by members of a private polyamorous (or similar) group. Accounts are created by group administrators; there is no public self-service signup. If you use PolyCal, you are sharing scheduling and relationship-context data with other members of that group according to the rules below.

2. Information we store

We store data needed to run scheduling, messaging, and optional external calendar sync in our application database (SQLite locally, or a hosted libSQL/Turso database when configured).

Account and profile

  • Username, display name, optional profile bio, avatar image, theme preference, and time zone
  • Password stored only as a one-way bcrypt hash (never in plain text)
  • Role and account status (for example active, paused, or deleted)
  • Optional gender field when set by an administrator
  • Optional notification email address and whether it has been verified
  • Notification and feed preference settings
  • Login-related metadata such as last login time and login count
  • Short-lived tokens for email verification and password reset

Scheduling and group content

  • Event and sleeping proposals (titles, descriptions, notes, times, recurrence, locations, icons)
  • Invitees, votes, poll time slots, comments, and attached images
  • Places (including optional street address and bedroom labels) and residency relationships
  • Sleeping-partner relationships within the group
  • Feed / network chat messages, comments, likes, link previews, and images
  • In-app notification dismissals and an append-only activity log of important account and app actions
  • Optional product-feedback submissions (text, screenshots, and basic device diagnostics when you send feedback)

Sessions and security

  • Signed-in sessions use Auth.js JWT cookies that are HttpOnly (and Secure in production). Session tokens are not stored in browser LocalStorage or SessionStorage.
  • Rate-limit records may temporarily associate IP addresses with login or password-reset attempts to reduce abuse.

3. Google user data (Calendar connection)

Connecting Google Calendar is optional. Google is used only for calendar sync — not as your PolyCal login. The use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. That information is used solely to provide or improve the user-facing Google Calendar sync feature in PolyCal.

Access

With your consent we request these scopes:

  • https://www.googleapis.com/auth/calendar.events — create, update, and delete only the events PolyCal syncs on your behalf
  • https://www.googleapis.com/auth/calendar.calendarlist.readonly — list calendars you can write to so you can choose a target calendar

We also read your Google account email (userinfo) to show which Google account is connected. We do not import or store the contents of your existing Google Calendar events into PolyCal.

Use

Sync is one-way from PolyCal → your chosen Google calendar for proposals you are involved in (as proposer or invitee). We write titles, descriptions, times, location text, and related metadata derived from PolyCal; sleeping arrangements export as all-day free/transparent events with the PolyCal sleeping title. We do not use Google user data for advertising, analytics products, credit decisions, or to train generalized AI/ML models.

Storage

We store: your Google account email, the selected calendar id, encrypted OAuth access and refresh tokens (AES-256-GCM at rest), and mapping rows that link PolyCal proposals to Google event ids we created. Tokens are never stored in browser LocalStorage.

Sharing

Google OAuth tokens and Google Calendar API responses are not shared with other PolyCal group members, sold, or transferred to advertising or data-broker platforms. Event content written into your Google calendar may reflect PolyCal group scheduling data you already see in the app.

Human access (Limited Use)

Limited Use restricts humans from reading Google user data except in narrow security/legal cases. PolyCal administrators do not have access to any Google Calendar information (tokens, calendar lists, or Google event payloads). Admin impersonation of another user disables all Google Calendar API and OAuth calls for that session so an administrator cannot connect, list, sync, or disconnect Google Calendar while impersonating.

Deletion

In Profile & Settings you can disconnect calendar integration. Disconnecting (or an administrator deleting your account) revokes the Google OAuth token when possible, deletes encrypted tokens and Google account/calendar fields from PolyCal, and deletes local Google event-id mappings. Events already written to your Google Calendar remain there until you delete them in Google Calendar (or revoke PolyCal in your Google Account permissions).

4. Optional iCal / email calendar delivery

Instead of (or in addition to workflows involving) Google, you may configure iCal (.ics) delivery: download in the app, email attachment to your verified notification email, or both. Pending .ics payloads may be stored briefly until you download them.

5. Email and push notifications

When email is configured for the deployment, transactional and notification messages are sent through Resend using the deployment's configured "from" address. That can include verification links, password-reset links, credential notices, schedule/notification alerts you opted into, and calendar .ics attachments.

When web push is configured, PolyCal stores browser push subscription endpoints and keys so we can deliver notifications you enable. Push payloads may include short titles, bodies, and deep links into the app.

An SMS preference may exist in notification settings for future use; the current product does not send SMS unless a provider is later configured.

6. How we use information

We use stored information to:

  • Authenticate you and keep your session secure
  • Operate group scheduling, voting, feed chat, and people/places features
  • Enforce group visibility rules (for example masking sleeping details from uninvolved members when enabled)
  • Send the notifications and calendar sync you configure
  • Allow administrators to manage accounts and group settings
  • Investigate abuse, fix bugs, and maintain the service (including activity logs)

We do not sell personal information. We do not use third-party advertising or analytics SDKs in the product.

7. Sharing within your group and with processors

Within your PolyCal group: other members (and administrators) can see content according to product rules — for example open proposals, feed posts you make, places, and sleeping details when they are involved or when admin visibility settings apply. PolyCal is a shared group tool; treat it as visible to your group, not private from them.

Service processors (only when the deployment enables them):

  • Hosted database provider (Turso/libSQL) — stores application data
  • Hosting provider (for example Vercel) — runs the web application
  • Resend — delivers email
  • Google — OAuth and Calendar API when you connect Google Calendar
  • Browser push services (via the Web Push protocol and VAPID keys) when you enable push

Administrators can manage PolyCal accounts and group settings, but they do not receive Google Calendar tokens or Google Calendar contents. Impersonation cannot call Google Calendar APIs (see Google user data above).

8. Retention and deletion

Delete your account yourself

In Profile & Settings → Your data you can permanently delete your own account. You confirm with your password and a typed confirmation phrase; no administrator involvement is required. Deletion is immediate and cannot be undone, and you are signed out on every device.

When you delete your account, PolyCal:

  • Erases your profile fields — display name (replaced with "Former User"), username, bio, gender, uploaded avatar image, notification and feed preferences, notification email, and verification status
  • Deletes your browser push subscriptions, so no further push notifications are delivered to your devices
  • Revokes and deletes your Google Calendar connection (encrypted tokens, selected calendar, account email) and the local event-id mappings
  • Deletes your sleeping-partnership links and residency records
  • Deletes places you created and archives proposals you authored
  • Replaces your password with an unusable value and invalidates all existing sessions

What remains, and why

PolyCal is a shared group tool, so a small anonymized tombstone record is kept instead of hard-deleting your row: group history — past feed posts and comments, resolved schedule history, and the append-only activity log — references your account, and removing that reference would corrupt other members' records. The tombstone carries no profile content. Product-feedback submissions you sent may also be retained for operational history. Events already synced into your Google Calendar stay in Google until you delete them there.

Export and correction

Before deleting, use Download my data in Profile & Settings to save a JSON copy of your profile, preferences, authored proposals, and partnership summary. Most profile fields can be corrected directly in Profile & Settings; for anything you cannot change yourself, contact your group administrator.

Ongoing retention

While your account is active, we retain account and scheduling data for as long as the service is operated. Password-reset and email-verification tokens expire automatically and are cleared on deletion. Administrators can also pause or delete accounts through the admin tools, which performs the same erasure described above.

9. Security

We use hashed passwords, HttpOnly session cookies, encrypted Google OAuth tokens at rest, server-side validation of inputs, and deny-by-default authorization checks on protected routes and actions. No method of transmission or storage is perfectly secure; protect your password and device access.

10. Children

PolyCal is intended for adults 18 years and older. It is not directed at anyone under 18, and we do not knowingly collect personal information from minors.

11. Changes

We may update this policy as the product changes. The effective date at the top will be revised when material changes are published at this URL.

12. Contact

For privacy questions or data requests, contact your PolyCal group administrator, or email support@polycal.net.

Terms of Service · Back to sign in