[ timegarden /// privacy policy ]

Privacy Policy

Last updated: July 6, 2026

timegarden is a calendar that shows you where your time actually goes. Doing that well means handling some genuinely personal data — your schedule, your screen activity, and (if you turn it on) transcripts of your meetings. This page explains exactly what we collect, why, and what we never do with it.

What we collect

Account. When you sign in with Google we receive your name, email address, and profile picture. We use these to identify your account and nothing else.

Calendar data. Events you create in timegarden, and — if you connect Google Calendar — the events we import on your behalf (titles, times, attendees, locations). Your ratings, tags, feelings, and written reflections are stored alongside them.

Screen activity. If you connect a computer or iPhone, the sync agent uploads spans of app usage: the app name, the window title, and the start and end time. No screenshots, no keystrokes, no content of what you were working on. Time when you are away from the keyboard or your screen is locked is excluded before anything leaves your device.

Meeting transcripts. If you install the recorder, audio from your meetings is transcribed in ~30-second chunks and the resulting text is attached to the calendar event. Audio is processed for transcription and is not stored; only the text transcript is kept. You are responsible for telling participants they are being recorded — consent laws apply where you live.

Bookings. When a guest books time with you, we store the name and (optional) email they enter, and the slot they picked.

Todos. If you connect a todo service (e.g. Todoist), we access your tasks to show them beside your calendar. We don't copy your task history to our servers beyond what's needed to display and sync them.

What we never do

We do not sell your data. We do not use it for advertising. We do not train AI models on it. No human at timegarden reads your calendar, activity, or transcripts except with your explicit permission to debug a problem you've reported.

Where it lives

Your data is stored in a Supabase (PostgreSQL) database hosted in Sydney, Australia, encrypted in transit and at rest. Access is enforced row-by-row at the database level: your data is readable only by your signed-in account. Availability you explicitly publish for booking (free/busy shape only — never event titles or attendees) is the single exception, since guests need it to book you.

A copy of your workspace also lives in your own browser (localStorage) so the app opens instantly and works offline.

Processors we rely on

We use a small number of infrastructure providers to run the service: Supabase (database, authentication), Google (sign-in and calendar sync, at your request), and a transcription provider (Groq or OpenRouter, only if you use the meeting recorder — audio chunks from your own recordings are sent for transcription and not retained by us; no Google user data is ever included). If you connect Todoist, your tasks flow through their API under their terms.

Google user data

timegarden's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Calendar data is used only to display and sync your calendar inside timegarden — never for advertising, never sold, never used to train models.

Who we share Google user data with

Google user data (your Google profile details and Google Calendar events) is shared with exactly one subprocessor: Supabase, which hosts our database and processes that data solely on our instructions to store and sync your calendar. We do not share, transfer, or disclose Google user data to any other third party. In particular, Google user data is never sent to any AI or machine-learning provider (including Groq and OpenRouter), never shared with advertisers or data brokers, never sold, and never transferred as part of any analytics service. The only exceptions are: if you explicitly direct us to (for example, publishing free/busy availability so a guest can book you — which exposes time shapes only, never event titles or attendees), or if disclosure is required by law, in which case we will notify you unless legally prevented.

Google user data and artificial intelligence

timegarden's optional AI features (meeting notes and the weekly review) operate only on content you create yourself — your recorder transcripts and the events you log directly in timegarden. Data obtained from Google APIs is segregated in the application and excluded from every AI request: events imported from Google Calendar, including their titles, attendees, locations, descriptions, and times, are never included in any prompt sent to an AI provider, and we never use Google user data to develop, improve, or train generalized or non-generalized AI or machine-learning models. This exclusion is enforced in the application code at the point where AI requests are constructed.

How we protect your data

Encryption: all data is encrypted in transit (TLS 1.2+) and at rest (AES-256) on our database infrastructure. Access control: row-level security is enforced at the database layer, so each record is readable only by the authenticated account that owns it; anonymous clients write through narrow, validated server-side functions and can never read data back. Tokens: Google OAuth tokens are stored server-side, encrypted at rest, restricted to the single function that needs them, and never exposed to other users or third parties. Least privilege: administrative credentials are held only in server-side secret storage, never in client code. Retention: raw location points (if you enable background location) are deleted automatically after 7 days; deleted accounts are erased within 30 days. Incidents: if a breach affects your data, we will notify you promptly at your account email.

Your controls

You can disconnect Google Calendar, screen-time tracking, the recorder, or your todo service at any time from the app menu — each stops the corresponding data flow immediately. To delete your account and all synced data, email us and we'll remove it within 30 days. Local data can be cleared by clearing your browser storage.

Changes

If this policy changes in a way that matters, we'll say so in the app before the change takes effect.

Contact

Questions or deletion requests: hello@timegarden.ai