← Back to VoiceCal

Privacy Policy

Effective date: October 7, 2026 Version: 1.7

This Privacy Policy describes how VoiceCal LLC ("VoiceCal," "we," "us," or "our") collects, uses, stores, and shares information when you use our website at voicecal.app and our scheduling service (together, the "Service").

We've tried to write this in plain English. If anything is unclear, email privacy@voicecal.app and we'll explain.


1. Who we are

VoiceCal is operated by:

VoiceCal LLC 9435 Waterstone Blvd, Ste 140-300 Cincinnati, OH 45249 United States

VoiceCal LLC is the data controller for personal data processed through the Service.

For privacy questions, data requests, or account deletion: privacy@voicecal.app.


2. Summary of what we collect and why

WhatWhyHow long we keep it
Your name, email, and Google account profile (from Google sign-in), or, if you sign in with email instead, your email address and a hashed (never plain-text) passwordTo create and identify your accountUntil you request deletion
Google Calendar OAuth tokens (encrypted), one set for each Google account you connectTo create and manage events on your calendar at your request, and to check when you're busyUntil you remove that Google account or delete your VoiceCal account
Google accounts you connect: each account's email address (which we learn from its primary calendar), a name for the account if you give it one, and whether it needs reconnecting; your calendar on/off switches; and the calendar you've chosen for new events (as calendar IDs, often an email address)To show you which account is which, use each account's calendars the way you've set them up, and put new events where you askedUntil you remove that Google account (which also removes its email address, name, and switches) or delete your VoiceCal account. If your chosen calendar for new events was on that account, that choice is deleted too, and new events go to another calendar you've switched on
Google Calendar data we read on your behalf: your events (title, time, description, guests, organizer), your free/busy times, and your list of calendars (see Section 4)To show you your calendar, find the event you ask to change, and find open times you can shareWe do not store it: we read it from Google when a feature needs it. The exceptions are records of events you create through VoiceCal, the Google event ID and link of meetings created when you finalize a TeamAvail poll, and LiveAvail bookings (rows below), and a short-lived in-memory copy of your calendar list, including calendar names (up to 5 minutes)
Your preferences (timezone, default meeting length, theme)To make the app work the way you've set it upUntil you change them or delete your account
Records of events you create through VoiceCal (title, date, time, attendees, description, and which Google account and calendar it went to)To display your event historyIndefinitely, until you request deletion
A monthly count of your smart actions (requests our AI processes, spoken or typed — a number only, never the content)To enforce your plan's monthly limitA new count starts each calendar month; past months' counts are kept until you delete your account
Names and email addresses of people you invite (attendees, people you add to an existing meeting, poll participants, share recipients)To send invitations, record responses, and suggest people you've invited beforeIndefinitely, until you remove them or request deletion
LiveAvail bookings: the booker's name and email, the booked time, and the ID of the Google Calendar event we createdTo keep a record of bookings made through your LiveAvail linksIndefinitely, until you request deletion
Reminders you set (what to remind you about, the person and notes you mention, the time, and the email address to send it to); your reminder settings (a separate email address for reminders, if you set one, and saved reminder contacts — a label and email address for people you often send reminders to); and, if you turn on lock-screen reminders, your browser's push subscription (a delivery address and keys, and your browser type)To send the reminder as a push notification and, where your plan includes it, by emailReminders: until you delete them or your account. Reminder settings and saved contacts: until you change them or delete your account. Push subscriptions: until you turn them off, your browser stops accepting them, or you delete your account
The text of what you say or type to VoiceCalTo parse it into a calendar event using AIWe do not store this on our servers, unless you choose to include it in an error report you send us (see "Feedback you send us" below). A short-lived copy may be kept in your own browser if you leave the confirmation screen partway through creating an event — see Section 10. See Section 5 for processor retention
A recording of what you say, on devices where your browser can't transcribe speech reliably (see Section 5)To turn your speech into text using AI transcriptionWe do not store the audio or keep a copy of it; we keep only an estimate of how many seconds of audio you've sent this month, for cost tracking. See Section 5 for processor retention
Feedback you send us from inside the app: your message, whether it's a bug or an idea, and — only if you leave "Include these details" on — the page you were on, your device and browser type, screen size, time zone, app version, and for an error report what you said and the error you saw, and whether you spoke or typed itTo fix problems, improve VoiceCal, and reply to you. Feedback is always linked to your account; we don't accept anonymous feedbackUntil you delete your account or ask us to delete it
A count of how many times you've used certain features recently (for example, booking a slot, or checking a page's availability), linked to your account if you're signed in, or, on our public LiveAvail booking pages, to your IP addressTo stop any one person or address from overloading a feature or a page (for example, someone repeatedly hitting a public booking page)See Section 7

We do not collect: browser fingerprints, advertising identifiers, location data from your device, or analytics tracking from third parties.


3. Information we collect when you sign in

You can sign in with your Google account, or with your email address — either with a password or with a one-time code we email you. If you use email, our authentication provider (Supabase) stores your email address and, if you set one, your password in hashed form; we never see or store your password in plain text. Sign-in codes are sent by our authentication provider.

When you sign in with your Google account, Google sends us:

We use this information to create your VoiceCal account and identify you on return visits. We do not display or use your profile picture in the Service today, but the URL is stored by our authentication provider as part of the standard sign-in flow.

We use the OpenID Connect scopes openid, email, and profile for sign-in. We do not request any additional Google scopes during sign-in.


4. Information we collect when you connect Google Calendar

Connecting your Google Calendar is separate from signing in. When you connect Calendar, we ask Google for these three permissions ("scopes"), and nothing broader:

ScopeWhat VoiceCal uses it for
https://www.googleapis.com/auth/calendar.eventsCreating events you ask for; showing your upcoming events in VoiceCal; opening a single event to show you its details; moving, editing, and deleting events you ask us to; adding guests to meetings you organize; undoing a delete
https://www.googleapis.com/auth/calendar.freebusyChecking when you're busy — only busy start and end times, never event details — to find open times for QuickAvail and LiveAvail, and to draw the day ribbon. VoiceCal checks that a connection still works using the calendar list instead (see the next scope); only for an older connection that hasn't granted that permission, and only while its main calendar is switched on, does VoiceCal use this scope for that check
https://www.googleapis.com/auth/calendar.calendarlist.readonlyReading the list of every calendar in each Google account you connect: its ID, name, color, whether it's shown in Google Calendar, and your access level (for example, whether you can edit it). A calendar follows the switch you've set for it in Settings → Calendars; until you set one, it follows whether it's shown in Google Calendar. We hold this list in server memory for up to 5 minutes and show the names to you in Settings and on the confirmation screen. We store a calendar's ID (often an email address) only when you switch it on or off, choose it as where new events go, or create an event on it through VoiceCal

When you grant access, Google sends us:

We encrypt these tokens with AES-256-GCM before storing them, using a key that is kept outside the database, so the Service can act on your behalf.

You can connect more than one Google account. Each one is stored separately and encrypted the same way described above, and can be removed on its own from Settings → Calendars. You can also give each one a name there; until you do, VoiceCal shows a name it works out from the account's email address, which isn't stored. Removing a Google account asks Google to revoke VoiceCal's access to it — this also ends VoiceCal's access to that same Google account from any other VoiceCal login it's connected to — and deletes its stored tokens, its calendar switches, its name if you gave it one, and, if it was on that account, your chosen calendar for new events (new events then go to another calendar you've switched on). Your other connected Google accounts are not affected.

What we do with your Google Calendar

What people you share availability with see

Google API Services User Data Policy

VoiceCal's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, for data we receive from Google (your Google account profile and your Google Calendar data):


5. Third parties we share data with

We use the following service providers ("sub-processors") to operate VoiceCal. We share with each only the data needed for them to do their job.

Anthropic (Claude API)

We send the text you type or speak to VoiceCal to Anthropic's Claude API to parse it into structured event data (title, date, attendees, etc.). The payload includes your transcript and any follow-up answers you give to clarifying questions. We do not send your name, email, or any account identifier to Anthropic.

AI training. Under Anthropic's commercial terms, Anthropic does not train its models on data submitted via its API. We do not authorize Anthropic to use your data for model training under any other arrangement.

Retention at Anthropic. Under Anthropic's standard commercial terms, API inputs and outputs may be retained by Anthropic for up to 30 days for trust-and-safety and abuse-monitoring purposes, after which they are deleted. We have not opted into any additional retention beyond this default. If Anthropic offers and we enable a zero-retention configuration in the future, we will update this policy.

See Anthropic's commercial terms and privacy policy for details.

OpenAI (speech-to-text on some devices)

On some devices (see "A note on speech transcription" below), VoiceCal records what you say and sends the recording to OpenAI's transcription API to turn it into text. The payload is the audio recording itself (recording stops automatically after 30 seconds, and we refuse anything over 3 MB), the name of the transcription model, and a short fixed instruction from us describing the kind of speech to expect (meeting times). We do not send your name, email, or any account identifier to OpenAI. The text OpenAI returns is then handled exactly like typed text: it is sent to Anthropic as described above.

VoiceCal does not save the recording. It passes through our server only for as long as it takes to send it to OpenAI and receive the text back, and it is never written to our database or our logs.

AI training. Under OpenAI's published API data-usage terms, OpenAI does not train its models on data submitted via its API unless the customer opts in. We have not opted in.

Retention at OpenAI. Under OpenAI's published API data-usage terms, API inputs and outputs may be retained by OpenAI for up to 30 days for abuse-monitoring purposes, after which they are deleted, unless OpenAI is legally required to keep them longer. We have not opted into any additional retention beyond this default. If we enable a zero-retention configuration in the future, we will update this policy.

See OpenAI's API data-usage terms and privacy policy for details.

Google (Calendar API)

When you create an event, we send to the Google Calendar API: the event title, description, location, start and end times with timezone, and the email addresses of attendees. When you move, edit, or delete an event, or add people to it, we send Google the event ID and the change you confirmed (the new time, title, or description, or the new guests' email addresses), and whether Google should email the guests. When you finalize a TeamAvail poll, we send the meeting details and the participants' email addresses. When someone books through your LiveAvail link, we send the booking time and the booker's name and email. To read your calendar, we send Google the time range and calendars to look at. To check that a connection still works, we ask Google for that account's list of calendars. When you remove a Google account, we ask Google to revoke VoiceCal's access to it. When you delete a meeting, we look for its copies on the main calendars you've switched on in your other connected accounts, so we can remove the ones you were invited to. Section 4 describes what we read back and why.

Supabase (database and authentication)

Supabase hosts our database and handles user authentication. All data described in Section 2 that we store, we store in Supabase. Supabase hosts our database on Amazon Web Services infrastructure, in the US East (Northern Virginia) region.

Vercel (hosting)

Vercel hosts the VoiceCal application. As part of standard web hosting, Vercel records request metadata including IP addresses, user agent strings, and request paths. We do not access these logs except to investigate errors or abuse.

Resend (email delivery)

When you create a TeamAvail poll or share availability, we send invitation emails through Resend. The emails are sent from notifications@voicecal.app and include the poll or share title, your name (as organizer), the recipient's name, and a unique link.

When someone books through your LiveAvail link, we normally send a confirmation through Resend to them and to you (a daily limit on confirmation emails per link can skip them on very busy days). It includes your name, the booker's name (and, in your copy, their email), and the date and time booked. No other details from your calendar are included.

If you set an email reminder, we send it through Resend to the address you chose. It includes the reminder's details, and if it goes to someone other than you, your name (or, if you haven't set one, your email) as the person who set it.

When you send feedback from inside the app, we email a copy to our own inbox through Resend. It includes your account email, your message, and any details you chose to include, and replies from us come from a person, not an automated system.

Fastmail (email receiving and forwarding)

Replies to our notification emails, and inbound mail to support@voicecal.app and privacy@voicecal.app, are received by Fastmail. If a recipient replies to a VoiceCal invitation, or contacts us at these addresses, the message passes through Fastmail.

A note on speech transcription

If you use VoiceCal's voice input feature, your speech is turned into text in one of two ways, chosen automatically based on your device and browser:

When the built-in Web Speech API is used, depending on your browser:

We do not control and are not responsible for how your browser implements speech recognition. On either path, you can type instead of speaking if you prefer that no audio leaves your device.


6. Information we do not collect or use

To be explicit:


7. How long we keep your data

DataRetention
Account record (name, email, Google IDs)Until you request deletion
Google OAuth tokens (encrypted), one set for each Google account you connectUntil you remove that Google account or delete your VoiceCal account
Google Calendar events and free/busy times we readNot stored; read from Google when a feature needs it. (The open times shown on a LiveAvail page may be held in server memory for up to 60 seconds.)
Your calendar list (IDs, names, colors, access level)Up to 5 minutes, in server memory only
A connected Google account's email address, a name for it if you give it one, and whether it needs reconnecting; your calendar on/off switches; and the calendar you've chosen for new events (as calendar IDs, often an email address)Until you remove that Google account (which deletes its email address, name, and switches together) or delete your VoiceCal account. If your chosen calendar for new events was on that account, that choice is deleted too, and new events go to another calendar you've switched on; otherwise it isn't affected
LiveAvail bookingsIndefinitely, until you request deletion
Your preferences (timezone, theme, defaults)Until you change them or delete your account
Event records (title, date, attendees, description, and which Google account and calendar it went to)Indefinitely, until you request deletion
TeamAvail polls and availability shares (including the Google event ID and link of a finalized poll's meeting)Indefinitely, until you request deletion
Anthropic API inputs (transcripts)Up to 30 days at Anthropic, then deleted
OpenAI API inputs (voice recordings, on devices that use VoiceCal's transcriber) and the resulting textNot stored by VoiceCal; up to 30 days at OpenAI, then deleted
Vercel hosting logsPer Vercel's retention policy (approximately 72 hours for runtime logs)
Feedback you send us (and our copy in our email inbox)Until you delete your account or ask us to delete it
Feature-use counts, by account or IP address (see Section 2)Each count covers a short period (30 minutes, an hour, or a day) and is reset when that period ends. Old counts are deleted by an automatic clean-up that runs as the service is used, usually within a few days of the period ending. We don't guarantee an exact deletion time

We retain event records indefinitely because we display your event history. Plan limits are enforced separately, using the monthly count of smart actions described above — not your event records. You can delete individual events at any time within the Service.


8. Removing a Google account vs. deleting your account

These are two different actions, and they have different effects.

Removing a Google account (Settings → Calendars → Remove, next to that account):

Deleting your account (email privacy@voicecal.app):


9. Information about people you invite

When you create an event with attendees, add people to a meeting, create a TeamAvail poll with participants, or an availability share with a recipient, you provide us with their names and email addresses. We store this information so the Service can send invitations and record responses. We also remember the name and email of people you've added to meetings so we can suggest them next time; you can remove anyone from those suggestions. When someone books through your LiveAvail link, they give us their name and email, which we store with the booking and add to the event on your calendar. When you send a reminder to someone else, we store their email address with the reminder (and in your saved reminder contacts, if you save them) and email them the reminder with your name as the sender.

We process this third-party data to perform the service you requested and in our legitimate interest in delivering invitations on your behalf. The invitations clearly identify you as the sender.

You are responsible for having an appropriate basis to share your contacts with us and for inviting only people who reasonably expect to hear from you.

If you are someone who has received an invitation from a VoiceCal user and you want your information removed from our system, email privacy@voicecal.app and we will delete it within 30 days. You do not need to be a VoiceCal user to make this request.


10. Cookies and local storage

We use cookies for:

These cookies are strictly necessary to operate the Service and do not require consent under EU/UK ePrivacy rules. We do not use cookies for tracking or advertising.

We use browser local storage for the following:

None of this is sent to our servers on its own; a restored event is sent only when you tap Create. Otherwise it stays in your browser.


11. Legal bases for processing (EU/UK/Switzerland users)

If you are in the European Economic Area, the United Kingdom, or Switzerland, GDPR (and UK GDPR) require us to identify the legal basis for each purpose of processing your personal data. We rely on the following bases:

PurposeLegal basis
Creating and operating your account; transcribing and parsing your scheduling requests; creating events on your calendar; sending invitations you initiatePerformance of a contract (Art. 6(1)(b)) — necessary to provide the service you signed up for.
Storing event records, settings, and preferencesPerformance of a contract (Art. 6(1)(b)) — required to deliver service features.
Operating the service securely (logging, abuse prevention, fraud detection)Legitimate interests (Art. 6(1)(f)) — our interest in running a secure, reliable service.
Responding to legal requests and complying with legal obligationsLegal obligation (Art. 6(1)(c)).
Defending or pursuing legal claimsLegitimate interests (Art. 6(1)(f)).
Reviewing and answering feedback you choose to sendLegitimate interests (Art. 6(1)(f)) — our interest in fixing problems you report and improving the service.

If we ever rely on your consent for a specific activity (we do not today), we will say so clearly, and you may withdraw consent at any time without affecting the lawfulness of earlier processing.

Automated decision-making. We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects about you.

Special category data. We do not seek or rely on special-category personal data (such as health, religion, or political opinions) within the meaning of GDPR Article 9. We do not use voice recordings to identify you. Because the text and speech you submit to VoiceCal are free-form, they may incidentally contain such information; if so, we process it only to the extent necessary to parse your scheduling request and do not use it for any other purpose.


12. International data transfers

VoiceCal is operated from the United States, and our service providers process data primarily in the United States.

If you access VoiceCal from outside the United States, your personal data will be transferred to, processed, and stored in the United States and other countries where our service providers operate. These countries may have data protection laws different from those of your country.

Transfers from the EEA, UK, and Switzerland. Where we transfer personal data of individuals in the European Economic Area, United Kingdom, or Switzerland to the United States or other jurisdictions that are not subject to an adequacy decision, we rely on appropriate safeguards, principally:

Each of our sub-processors named in Section 5 offers an appropriate transfer mechanism under its standard data processing terms. You may request a copy of the relevant safeguard by contacting privacy@voicecal.app.

By using the Service, you acknowledge these transfers.


13. Your rights

You have rights over your personal data. The specific rights you can exercise depend on where you live, but VoiceCal honors the following for all users regardless of location:

To exercise any of these, email privacy@voicecal.app. We will respond within 30 days.

Additional rights for EEA, UK, and Swiss users

In addition to the rights above, under GDPR (and UK GDPR), you have:

We encourage you to contact us first at privacy@voicecal.app so we can try to resolve your concern directly.

Additional rights for California residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the following rights:

Categories of personal information we collect. Identifiers (name, email, Google account ID); customer records (event titles, attendees, descriptions you provide); internet or other electronic network activity (timezone, settings, app usage); inferences drawn from the above only to fulfill your scheduling requests.

Sale and sharing. We do not sell or share your personal information as those terms are defined under the CCPA/CPRA. We do not engage in cross-context behavioral advertising. We honor Global Privacy Control (GPC) signals where technically feasible.

Sensitive personal information. We do not collect or use sensitive personal information for purposes that would trigger your right to limit its use under the CPRA.

To exercise your CCPA rights, email privacy@voicecal.app. You may also designate an authorized agent to make a request on your behalf; we will verify the agent's authority before responding. We will not discriminate against you for exercising your rights.


14. Security

We use industry-standard security measures appropriate to a service of our size:

We are continually improving our security practices. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

If we become aware of a security breach affecting your personal data, we will notify you and any relevant regulator where, and within the timeframes, required by applicable law.

If you believe your VoiceCal account has been compromised, email privacy@voicecal.app immediately.


15. Children's privacy

VoiceCal is not intended for children under 13, and we do not knowingly collect information from children under 13. If you believe a child has created an account, email privacy@voicecal.app and we will delete it.


16. Changes to this policy

If we change this policy, we will update the "Effective date" at the top and post the new version at this URL. For material changes, we will also notify you by email at the address associated with your account.

We review this policy at least annually.


17. Contact

For any privacy question, data request, or complaint:

Email: privacy@voicecal.app Mail: VoiceCal LLC, 9435 Waterstone Blvd, Ste 140-300, Cincinnati, OH 45249, United States

We aim to respond to all privacy emails within 30 days.